Main Categories
- +Signs, Symbols and Product Specifications (1)
- +Information management (5)
- +Business (2)
- +Services (2)
- +Measurement and Science (10)
- +Healthcare (20)
- +Environment (15)
- +Health and Safety (12)
- +Engineering (61)
- +ICT (21)
- +Manufacturing (41)
- +Agriculture and Food (17)
- +Construction (34)
- +Commercial and Consumer Goods (9)
- General (18)
The present document specifies technical requirements and corresponding assessment criteria for physical and virtual
network interfaces related to cybersecurity. The products with digital elements in scope, thereafter "network interfaces":
• are specified within the "technical description" of the "category of product" number "10" by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as:
"Physical network interfaces are products with digital elements that directly connect a device to a network via
an Application Programming Interface (API) provided by the interface drivers, typically operating at the data
link layer, and that feature hardware adapters to transmission media with corresponding firmware, typically
operating at the physical and data link layer.
Virtual network interfaces are products with digital elements that directly or indirectly connect a device to a
network via an API that emulates that of drivers of physical network interfaces, typically operating at the data
link layer.
This category includes but is not limited to wired and wireless network interface cards, controllers and
adapters, such as for Wi-Fi®, Ethernet, IrDA, USB, Bluetooth, NearLink, Zigbee®, or Fieldbus, as well as
purely virtual standalone products, such as virtual network interface cards, container network interfaces and
VPN interfaces".
• are only covered within the product context described in clause 4.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1], Annex I Part I under the conditions identified in Annex A.
Network interfaces intended for use in the industrial Operational Technology (OT) domain are excluded from the scope
of the present document, see prEN 50770 series [i.5].
Network interfaces whose intended purpose includes management or configuration of the product over the attached
network are excluded from the present document.
Network interfaces whose intended purpose includes routing, switching; or transfer of information from one attached
network to a different attached network are excluded from the present document.
The present document specifies technical requirements and corresponding assessment criteria for web browsers related
to cybersecurity. The products with digital elements in scope, thereafter "the products" are specified within the
"technical description" of the "category of product" number "2" by the Commission Implementing Regulation (EU)
2025/2392 [i.2] as:
• "Software products with digital elements that enable end users to access, render, and interact with web content
and services hosted on servers that are connected to networks such as the Internet. They typically include a
browser engine for interpreting and displaying content written in markup language (e.g. HTML), support for
web protocols (e.g. HTTP, HTTPS), the ability to execute scripts and manage user inputs as well as storage of
temporary or persistent data from websites (cookies).
This category includes but is not limited to standalone applications that fulfil the functions of browsers, embedded
browsers intended for integration into another system or application as well as browsers with AI agent integration."
The products are only covered within the product context described in clause 4. The present document specifies
technical characteristics and methods of assessment for:
• Standalone web browsers: standalone applications that fulfil the functions of web browsers
• Embedded web browsers: embedded browsers intended for integration into another system or application
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in Annex A.
Browsers with AI agent integration are out of the scope of the present document as well.
The present document specifies technical requirements and corresponding assessment criteria for Virtual Private
Networks related to cybersecurity. The products with digital elements in scope, thereafter "VPNs":
• are specified within the "technical description" of the "category of product" number "5" by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as: "Products with digital elements that establish an encrypted
logical tunnel that is constructed from the system resources of a physical or virtual network".
• are only covered within the product context described in clause 4 and the text of this clause.
In particular, the present document specifies technical characteristics and methods of assessment for:
1)
2)
3)
4)
Software that operates as a VPN client or endpoint
Software that operates as a node within a mesh VPN network
Software that operates as a VPN server
Remote data processing, specifically VPN server software performing the logical server role, and associated
software used for such VPN products
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in Annex A.
VPN hardware or appliances, and control mechanisms for mesh VPNs are excluded from the present document.
VPNs intended for use in the industrial Operational Technology (OT) domain are excluded from the scope of the
present document, see prEN 50770 series [i.5].
The present document specifies technical requirements and corresponding assessment criteria for Network Management
Systems related to cybersecurity. The products with digital elements in scope, thereafter "NMS":
• are specified within the "technical description" of the "category of product" number "6" by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as: "Products with digital elements that manage connected
network elements, such as servers, routers, switches, workstations, printers or mobile devices, by monitoring
them and controlling their network operations and configuration".
This category includes but is not limited to end-to-end management systems and dedicated configuration
management systems, such as controllers for software-defined networking.
• The products with digital elements in scope are only covered within the product context described in clause 4
of the present document.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in annex A.
This includes, but is not limited to, Mobile Device Management systems and Software Defined Networking, e.g when
an SDN-controller is a stand-alone product using a network management protocol as its South Bound Interface (SBI).
NMS intended for use in the industrial Operational Technology (OT) [i.18] domain are excluded from the scope of the
present document.
An NMS is a product controlling at least partially connected devices with network access. Despite its central
positioning, an NMS can be an aggregate of several components, including but not limited to: end-to-end management
systems, dedicated configuration management systems, or controllers for software-defined networking.
NMS can be composed of several components or can implement additional functions that are outside the scope of the
present document.
EXAMPLE:
Aggregate product design would be an implementation where the operating system acts as an
abstraction layer for the system(s) that host the NMS, or the networking interfaces.
The present document specifies technical requirements and corresponding assessment criteria for Security Information
and Event Management related to cybersecurity.
The products with digital elements in scope, hereinafter "SIEM" or "SIEM systems":
• are specified within the "technical description" of the "category of product" number 7 by the Commission
Implementing Regulation (EU) 2025/2392 [i.2] as: Products with digital elements that collect data from
multiple sources, analyse and correlate that data and present it as actionable information for security-related
purposes, such as threat and incident detection, forensic analysis or compliance purposes.
• are covered only within the product context described in clause 4.
The present document covers those products for the purpose of demonstrating compliance with the essential
cybersecurity requirements of Regulation (EU) 2024/2847 [i.1] Annex I, Part I under the conditions identified in
Annex A.
SIEM systems intended for use in the industrial operational technology (OT) domain are excluded from the scope of the
present document, see prEN 50770 series [i.5].
1.1
General
The present document specifies technical requirements and corresponding assessment criteria for operating systems
related to cybersecurity. The products with digital elements in scope, thereafter "the operating system":
• are specified within the "technical description" of the "category of product" number 11 of Annex III, Class I by
the Commission Implementing Regulation (EU) 2025/2392 [i.2] as:
"software products with digital elements that provide an abstract interface of the underlying hardware and
control the execution of software, and that may provide services such as computing resource management and
configuration, scheduling, input-output control, managing data, and providing an interface through which
applications interact with system resources and peripherals. This category includes but is not limited to real
time operating systems, general-purpose and special-purpose operating systems".
• are only covered within the product context described in clause 4.
The present document covers those products to demonstrate compliance with essential cybersecurity requirements in the
Regulation (EU) 2024/2847 [i.1] Annex I Part I under the conditions identified in Annex A.
The use of harmonised standards is voluntary.